Edit | Wu Shuo Blockchain, Grok, etc.
Crypto exchange Bitget confirmed in the early hours of September 25 that an unauthorized transfer occurred from a hot wallet. CEO Gracy Chen said that at 02:31 Beijing time on September 25, the security system detected abnormal outgoing transfers from some hot wallets. An initial assessment put the affected funds at approximately $351.6 million. The official statement said cold wallets remain secure, users’ account balances were not altered, and losses could be covered by a user protection fund totaling more than $464 million. The platform has suspended withdrawals, while deposits and trading remain open, and it pledged to publish a complete incident report including a root-cause analysis by 05:30 on September 26.
Before official statements were issued, on-chain analysts had already observed that wallets tagged with Bitget were consolidating and transferring assets worth about $178 million to $190 million to newly created addresses. The two sets of numbers coexist: $351.6 million is the exchange’s internal accounting, while about $180 million is the on-chain tally of assets linked to publicly tagged addresses.
The timing of the on-chain anomaly closely matches the time the official detection was made. Unchained recorded the visible outflow window as September 25, 02:31 to 04:55. During that period, a newly created address withdrew about 19.67 million USDT0 from an address tagged with a Bitget hot wallet. On Arbitrum, within about 6 minutes, it was swapped for about 7,111 ETH via UniswapX and 1inch Fusion, with the execution price up to about 5% above the market price. The on-chain observer DCF GOD was the first to point out this exchange. There is a possibility that stablecoins could be frozen by the issuer; after being converted to ETH, interception becomes harder.
After that, multiple Bitget-tagged wallets transferred ETH, USDT, USDC, AVAX, BNB, and XAUT into the same newly created address 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. Etherscan later labeled it as Bitget Exploiter 1. The funds were further split to other addresses, and cross-chain bridging appeared. Unchained also recorded that, within about 30 minutes, the same address received about 34.75 million USDT, 12.85 million USDC, and 3,000 XAUT; afterward, about one hour later, it received about 24,373 ETH from multiple tagged addresses as well. As of 04:55, there was still an outflow from Avalanche.
04:24, Arkham Intelligence analyst Emmett Gallic posted. He first reported about $178 million, updated at 04:35 to about $183 million, and said it involved three hot-wallet and one cold-wallet tagged addresses, with multi-chain collection. Here, the “cold wallet” comes from browser and analyst tags and is not automatically equivalent to the official internal hot/warm/cold three-tier classification. At 05:06, Bubblemaps issued an alert, saying that a total of about $180 million in multi-chain funds was sent to the same address. At 05:33, it updated to about $190 million. CryptoSlate cited its statistics, saying 15 transfers involved nearly $192 million across seven assets, with ETH accounting for about 44.4%.
05:30, Gracy Chen published a complete security notice on X, and the official website also posted an announcement at the same time. The official confirmed the affected amount was about $351.6 million, emphasizing that this incident only involved part of the hot wallet and warm wallet, and that the cold wallet was completely safe. User account balances were accurate; deposits and trading continued as normal. As a precaution, withdrawals were paused. Bitget said it had launched an emergency team within minutes after detection—marking and reporting the anomalous addresses—while also notifying law enforcement agencies and on-chain security companies. The official also stated clearly that before the investigation was completed, no guesses would be made about the attack path, and updates would be provided on progress every hour through official channels.
If the final figure of $351.6 million is confirmed, Bitget would move into an upper-tier position among major amounts in the history of centralized exchange thefts—but it would still be clearly smaller than the amount stolen from Bybit in February 2025.
At the time, Bybit’s Ethereum cold wallet was stolen during a routine reallocation of about 400,000 ETH, then worth approximately $1.4 billion to $1.5 billion—at the time, the largest single exchange theft on record. Subsequent investigations pointed to a targeted malicious script planted on the frontend of a Safe multi-signature wallet: the signer saw a normal transfer on the interface, but actually signed a transaction that replaced the implementation contract. As a result, control of the cold wallet changed hands. After that, the U.S. Federal Bureau of Investigation and other agencies attributed the attack to a cluster related to North Korea’s Lazarus. Bybit made up the loss with its own funds; afterward, it operated normally and users’ funds were not affected.
After Bybit’s cold wallet was stolen in February 2025, Bitget was one of the exchanges that was among the first to publicly offer help. The platform used its own funds to transfer 40,000 ETH to Bybit—worth about $105 million to $106 million at the time—to help ease withdrawal congestion. This loan had no collateral, no interest, and no fixed repayment deadline. Later, Bybit CEO Ben Zhou said in an interview that Bitget was the first to help, and they didn’t even sign a contract. Bitget also blacklisted the related addresses and said it could continue to provide support. About three days later, Lookonchain monitoring found that Bybit transferred the 40,000 ETH back, and Gracy posted to confirm it had been recovered.
Historically, in post-incident public reviews of thefts from centralized exchanges, the most common cause is that the hot-wallet private key or signing authority was obtained. Coincheck in 2018 (about $530 million), KuCoin in 2020 (about $280 million), and Bitmart in 2021 (about $150 million) all pointed to a compromise of联网热钱包密钥. Another type is that multi-sig and signing interfaces were bypassed: Bitfinex in 2016 was related to the multi-sig solution at the time; WazirX in 2024 saw its multi-sig control authority changed; and Bybit in February 2025 was stolen. In addition, there are compromises in the supply chain and operations, such as signer devices, wallet service providers, or internal permissions being exploited.
As of the time of this report, Bitget said it would check investigation progress on an hourly basis. The specific attack path (such as whether any private key leakage or interface vulnerability was involved) has yet to be fully disclosed in an official report.
